Unauthorized access to files in T-Systems products
The following products in the TAO 2.0 suite, in versions prior to 2602.00, are affected:
- Archivo;
- MyTAO;
- eStima;
- Buroweb.
INCIBE has coordinated the disclosure of a medium-severity vulnerability affecting several products in the TAO 2.0 suite, a management platform for public administration. The vulnerability was discovered by T-Systems’ internal security team.
This vulnerability has been assigned the following identifier, CVSS v4.0 base score, CVSS vector, and CWE vulnerability type:
- CVE-2026-7185: CVSS v4.0: 6.0 | CVSS AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N | CWE-22
The vulnerability, reported by the T-Systems team itself, has been fixed in version 2602.0.0 of the affected products. The general recommendation is to update to that version or any later version that includes these fixes.
CVE-2026-7185: a validation vulnerability has been identified in certain web features related to file management or upload in several products of the TAO 2.0 suite. This vulnerability could allow an attacker capable of interacting with the affected feature to attempt to access file system resources outside the scope intended by the application.
| Identificador CVE | Severidad | Explotación | Fabricante |
|---|---|---|---|
| CVE-2026-7185 | Media | No | T-Systems |



